Three Ledger bulletins, and the fix is an app update
Ledger published LSB 023, 024 and 025 on 27 August. The one with the widest reach sits in the Secure SDK rather than in any single app, and none of the three is repaired by updating device firmware.
Updating the firmware will not fix any of this. That is the sentence to carry away.
Ledger published three security bulletins on 27 August 2026: LSB 023, 024 and 025. Two concern the Ethereum app; the third is not about one app at all.
The one with the wider reach
LSB 023 describes a defect in the Ledger Secure SDK, the shared code every application compiles in. Per the bulletin, apps handle commands asynchronously, holding signing parameters in global state while a review screen waits, and the SDK did not stop the host sending another command in that interval — so each app had to reject one itself. An app that guarded every asynchronous entry point was safe; one that missed a single check left a window where parameters could be overwritten after the user read them, and the approval signed the new ones.
Exploiting it needs an adversary already controlling the device’s command exchange: a compromised wallet app, a hostile WebHID or WebUSB page, or host malware. Ledger reports no evidence of exploitation. Scope, per the bulletin: apps built against Secure SDK versions from August 2025 through v26.6.0, released 11 August 2026. The firmware is not affected.
The two Ethereum ones
LSB 024 — classified High, per Ledger’s published timeline — is an array-count truncation. A 16-bit element count was stored in an 8-bit field, so a list of 257 operations registered as 1; the device reviewed one entry, the signature covered the lot. It affects 1.19.0 through 1.22.2 and came from Felipe A. Manzano of Bitfinding via the bug bounty programme, with a variant reported independently by Florian Pradines through the same channel.
LSB 025, found by Ledger’s internal automated review, affects 1.20.0 through 1.22.2: the swap path checked a transaction’s address and quantity but not its nature, so a token approval could be signed in place of the payment, unseen. Both are fixed in 1.22.3, published 25 August; 1.22.2 was tagged without it.
The briefing
Open Ledger Live, update the apps, and read the version off the signer: Ledger states that firmware updates alone do not establish that affected apps have been replaced. For the Ethereum bugs the number is 1.22.3. LSB 023 has no single number: the correction reached apps through rebuilds against Secure SDK v26.6.1, re-published 21 August, so an older build lacks it.
None of this puts the recovery phrase at risk: the keys stay on the device. But a week thick with update notices is the weather phishing likes best. Nothing here needs your recovery phrase: not a bulletin, not an update prompt, not a support agent. It stays on paper or steel, off every keyboard and camera.
This is the trust-the-vendor question from our Ledger review, answered in public. A signer narrows your risk; it does not retire it, and crypto assets stay high-risk whatever version is installed — so read the bulletins, not our account of them.